The Financial Conduct Authority’s crypto authorisation gateway opens at 9:00 a.m. on 30 September 2026 and closes at 11:59 p.m. on 28 February 2027, according to the regulator’s gateway guidance and formal direction. The dates turn the UK’s new crypto regime into an immediate filing exercise: firms have a defined application window before full regulation begins on 25 October 2027, and missing it changes what they can do when that date arrives.
The timetable itself is not new. The FCA’s direction specifying both times and dates is dated 20 February 2026, and FinanceFeeds set out the five-month window on 1 September. The immediate development is operational. The gateway now opens in three weeks, the FCA has published the information expected in the application, and firms that wait beyond February lose access to the more permissive saving provision while their case is assessed.
Three Dates Determine Whether a Firm Can Keep Growing
The first date, 30 September 2026, is when the FCA’s online application form becomes available and the formal filing period begins. The second, 28 February 2027, is the last day on which an application for authorisation or a variation of permission can enter through the defined window. The third, 25 October 2027, is when the wider Financial Services and Markets Act cryptoasset regime takes effect.
The FCA says it expects to determine applications filed within the window before commencement. If it has not completed an in-window application by 25 October 2027, the legislation’s saving provision can allow the firm to continue providing specified crypto services until the application is finally determined, subject to the relevant conditions. That protection can also extend while a refusal is before the Upper Tribunal.
Missing 28 February Restricts New Business
A firm may still submit an application after 28 February 2027 and before the regime starts, but the FCA will not accelerate the assessment to compensate for the late filing. If the required permission has not been granted by 25 October, the applicant enters the statutory transitional provision rather than the saving provision.
That is a material commercial restriction. During the transitional period, the firm may conduct newly regulated UK crypto activities only as necessary to perform a contract entered into before it entered transition. It cannot enter new contracts with new customers, and it cannot sell new business to existing UK customers. The consequence is therefore broader than an onboarding freeze: the firm is limited to servicing pre-existing contractual obligations while the FCA decides its application.
Firms that do not apply must run off their UK crypto business before commencement. They receive neither the saving provision nor the transitional provision. Continuing regulated activity without authorisation could breach the general prohibition under section 19 of FSMA, while an already authorised business could breach section 20 by acting outside its permissions.
MLR Registration Does Not Convert Into Authorisation
The gateway applies to firms wishing to carry out the new regulated cryptoasset activities in or to the UK. These cover stablecoin issuance, operating a cryptoasset trading platform, dealing and arranging, custody, staking, lending and borrowing, subject to the statutory perimeter and any applicable exclusions.
Existing status does not provide an automatic pass. Firms registered under the Money Laundering Regulations must apply for FSMA authorisation if their activities fall within scope. The same point can affect businesses registered or authorised under the Payment Services Regulations or Electronic Money Regulations. Firms already authorised under FSMA for other financial services must apply to vary their permissions.
The distinction is significant because MLR registration focuses on anti-money laundering and counter-terrorist financing controls, while FSMA authorisation reaches governance, financial resources, conduct, systems and supervision. The change follows the pattern already visible in the European Union, where the MiCA register expanded to 329 records by mid-August after national registrations began giving way to full cryptoasset service provider licences.
The Application Runs Well Beyond an AML File
The FCA published a 68-page information document in July showing the expected structure of the authorisation form. The final online wording may still change, but the regulator says all crypto-specific sections are included and applicants will complete the parts relevant to their business model.
The common sections cover proposed permissions, client types, senior managers, controllers, close links and organisational structure. Applicants must provide a regulatory business plan, financial forecasts, an IT self-assessment and information on governance, compliance and risk. The supporting material also reaches financial crime controls, compliance monitoring, complaints handling and cryptoasset records management.
Activity-specific questions then test how the business works. A stablecoin issuer must explain redemption, disclosures and the structure and custody of backing assets. A custodian must document reconciliation, trust arrangements, third-party oversight and protection of the means of access to client assets. Trading platforms need policies covering access, market makers, algorithmic trading, conflicts, admissions, market abuse, post-trade transparency and any own-account or matched-principal activity.
That breadth explains why the available period should not be treated as five months in which to start preparing. The FCA expects boards to approve a credible implementation plan, firms to map their activities to the permission perimeter, and applicants to identify resources and costs before filing. Recent European experience offers the same warning: Czech applicants now face the CNB’s MiCA process, while the cost of full authorisation has already raised consolidation concerns.
The UK Gateway Opens as the MiCA Review Closes
September 30 carries a second European deadline, but it is not the opening of a new MiCA consultation. The European Commission opened its targeted MiCA review on 20 May 2026 and later extended the response deadline from 31 August to 30 September at 11:59 p.m. Central European Summer Time. The UK gateway opens that morning while the EU consultation closes that evening.
The exercises operate at different stages. UK firms are preparing applications under a regime that starts in October 2027. The Commission is collecting evidence on whether MiCA remains fit for purpose, including its scope, stablecoins, service-provider framework and activities such as staking, lending, decentralised finance and perpetual futures. Meanwhile, the existing EU framework is already producing licences, with ESMA adding 37 providers immediately after the main transition ended.
For groups serving both markets, the shared date creates two different workstreams: finalising a UK permission strategy while deciding whether to seek changes to the EU framework. The FCA filing has the more immediate operational consequence. An application submitted inside the window preserves a route to continued business during assessment; a late application can leave the firm servicing old contracts without writing new ones.
